C To Ast
Narwhal-Lab/MagicSkills
Parse C source code into an Abstract Syntax Tree (AST). An agent skill from Narwhal-Lab/MagicSkills.
威胁归因方法论:钻石模型、基础设施图谱、置信度分级与归因报告. An agent skill from dslsdzc/rev-skills.
$ npx skills add dslsdzc/rev-skills --skill re-attribution -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install dslsdzc/rev-skills re-attribution --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/re-attribution .claude/skills/re-attribution && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "re-attribution" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-attribution into .claude/skills/re-attribution/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-attribution", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-attributionType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add dslsdzc/rev-skills --skill re-attribution -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install dslsdzc/rev-skills re-attribution --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/re-attribution .agents/skills/re-attribution && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "re-attribution" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-attribution into .agents/skills/re-attribution/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-attribution", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add dslsdzc/rev-skills --skill re-attribution -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install dslsdzc/rev-skills re-attribution --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/re-attribution .cursor/skills/re-attribution && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "re-attribution" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-attribution into .cursor/skills/re-attribution/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-attribution", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/dslsdzc/rev-skills.git --path .claude/skills/re-attribution--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add dslsdzc/rev-skills --skill re-attribution -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install dslsdzc/rev-skills re-attribution --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/re-attribution .gemini/skills/re-attribution && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "re-attribution" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-attribution into .gemini/skills/re-attribution/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-attribution", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install dslsdzc/rev-skills re-attributionInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add dslsdzc/rev-skills --skill re-attribution -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/re-attribution .github/skills/re-attribution && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "re-attribution" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-attribution into .github/skills/re-attribution/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-attribution", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add dslsdzc/rev-skills --skill re-attribution -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install dslsdzc/rev-skills re-attribution --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/re-attribution .opencode/skills/re-attribution && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "re-attribution" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-attribution into .opencode/skills/re-attribution/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-attribution", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
re-attribution威胁归因方法论:钻石模型、基础设施图谱、置信度分级与归因报告. An agent skill from dslsdzc/rev-skills.
Re Attribution is an agent skill from dslsdzc/rev-skills. 威胁归因方法论:钻石模型、基础设施图谱、置信度分级与归因报告。 触发词:归因、APT、attribution、攻击者身份、基础设施图谱、钻石模型、威胁组织。
Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/decision-tree.md` and `references/gotchas.md`).
It sits in Security. It works with Python. The repository describes itself as: 122 个逆向工程 AI 技能(可发布、跨平台):恶意软件分析 / 软件逆向 / 固件嵌入式 / 协议逆向 / 移动应用 / 脱壳反混淆 / 软件破解 / 漏洞挖掘 / 托管代码 / 取证情报 / CTF。 The licence is Apache-2.0.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit bd21db8. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
aptpippython3dnfbrewgoFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use pip, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Re Attribution loads about 1.1k tokens when it runs, and up to ~3k if it reads all its reference files. Until then it costs about 23 tokens; SKILL.md has 237 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from dslsdzc/rev-skills at commit bd21db8, republished under its Apache-2.0 licence (© dslsdzc). 237 words, ~1,106 tokens.
.claude/skills/re-attribution/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.apt install whois / dnf install whois;macOS brew install whois;Windows 用 WSL 分支(见 [[re-analyze/platform-tips]])pip install python-whois;验证: python3 -c "import whois"projectdiscovery/dnsx releases 或 go install github.com/projectdiscovery/dnsx/cmd/dnsx@latest;验证 dnsx -version(PyPI 同名包与官方工具无关,别混用)whois -h whois.cymru.com <IP> 返回 AS 号与归属(Team Cymru 公开接口)apt install misp 在发行版源不存在)或轻量替代(本地 CSV/图文件)pip install networkx(python 图分析);验证: python3 -c "import networkx"按顺序执行;全部内容脱敏处理(红线:不指向具体组织/受害者身份,只用代号与抽象描述)。
钻石模型定位:
基础设施图谱:
# 域名/IP/证书关联聚类(示例流程,工具可替换)
# 1) 收集 C2 域名/IP → whois 注册信息(注册者/邮箱/NS/ASN)
# 2) 证书透明日志(crt.sh)查共用证书 → 关联其他域名
# 3) dnsx 主动枚举关联子域/NS 记录(被动 DNS 接口看解析历史)
# 4) networkx 图聚类:共享注册者/证书/NS/ASN 的节点合并能力与样本归因:
置信度分级:
报告:
# 归因报告(内部)
- 结论:<等级> —— 与 <代号> 活动为同一活动方(置信度:中)
- 证据链:1) 唯一注册邮箱(whois,查询时间) 2) 共用证书(crt.sh) 3) 代码唯一字符串(样本对照)
- 反证/未决项:时间线缺口;注册信息匿名(GDPR)
- 方法边界:未验证 C2 行为;无法判定项清单© dslsdzc, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 2 other files (references) in .claude/skills/re-attribution of dslsdzc/rev-skills.
Open the folder on GitHubat commit bd21db8
We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in dslsdzc/rev-skills, which our catalogue first saw on October 7, 2026.
Re Attribution next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Re Attribution this skilldslsdzc/rev-skills | 125 | 1 repos | ~1.1k | Automated safety check: Pass | Apache-2.0 | |
| C To AstNarwhal-Lab/MagicSkills | 316 | — | ~1.1k | Automated safety check: Pass | MIT | |
| Security AuditTheDecipherist/claude-code-mastery | 550 | — | ~1.3k | Automated safety check: Notes | MIT | |
| Vpn Security CheckSergei-thinker/vpn-setup | 189 | — | ~1.5k | Automated safety check: Notes | MIT | |
| Banditalpha-omega-security/scrutineer | 231 | — | ~615 | Automated safety check: Notes | MIT | |
| Python Reviewliuyanghejerry/Clausura | 204 | — | ~164 | Automated safety check: Pass | MIT |
Narwhal-Lab/MagicSkills
Parse C source code into an Abstract Syntax Tree (AST). An agent skill from Narwhal-Lab/MagicSkills.
TheDecipherist/claude-code-mastery
Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge.
Sergei-thinker/vpn-setup
Infrastructure security audit for VPN server. An agent skill from Sergei-thinker/vpn-setup.
alpha-omega-security/scrutineer
Run bandit against the Python source in the repository and map its hits into the findings shape.
liuyanghejerry/Clausura
Python 遗留代码审查:bare except、SQL 注入、反序列化、密钥、调试输出. An agent skill from liuyanghejerry/Clausura.
luongnv89/skills
Install local-first security hardening: pre-commit secret detection, offline dependency scans, static analysis, reports, and gated free CI.
dslsdzc/rev-skills
Captures an analyzable sample from a live system when the target leaves no file on disk, by finding abnormal executable memory and the execution context that reached it.
dslsdzc/rev-skills
函数式语言运行时逆向(Haskell/OCaml):闭包/堆对象模型、调用约定、数据流优先策略. An agent skill from dslsdzc/rev-skills.
dslsdzc/rev-skills
虚拟化逆向:VT-x/SVM、hypervisor 检测、VMCS/EPT 分析, 以及 Xen / QNX Hypervisor / Jailhouse / ACRN / Bao / Hyper-V·VMBus / XtratuM / LynxSecure / Quest-V 的分区与 vdev 语义。
dslsdzc/rev-skills
射频逆向:信号采集、频谱分析、解调、帧同步与协议恢复、重放. An agent skill from dslsdzc/rev-skills.
dslsdzc/rev-skills
UEFI/BIOS 固件:SEC/PEI/DXE/BDS 阶段判定、DXE 驱动、UEFI 模块、bootkit. An agent skill from dslsdzc/rev-skills.
dslsdzc/rev-skills
现代 C++ 二进制逆向:RTTI/异常/虚表恢复、ABI 识别、mangling 解码. An agent skill from dslsdzc/rev-skills.
Works with
Categories
威胁归因方法论:钻石模型、基础设施图谱、置信度分级与归因报告. An agent skill from dslsdzc/rev-skills. Re Attribution is an agent skill from dslsdzc/rev-skills.
Re Attribution fits situations like: security work in your project.
Run `npx skills add dslsdzc/rev-skills --skill re-attribution -a claude-code`. Or copy the skill folder (.claude/skills/re-attribution in dslsdzc/rev-skills) into .claude/skills/re-attribution in your project. Claude Code loads it when a task matches its description.
Run `npx skills add dslsdzc/rev-skills --skill re-attribution -a codex`. Or copy the skill folder (.claude/skills/re-attribution in dslsdzc/rev-skills) into .agents/skills/re-attribution in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add dslsdzc/rev-skills --skill re-attribution -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/re-attribution, .gemini/skills/re-attribution, .github/skills/re-attribution and .opencode/skills/re-attribution in your project.
Going by SKILL.md and its folder, Re Attribution needs the command-line tools its instructions call (apt, pip, python3, dnf, brew and go). Our summary lists: Python 3; Docker.
SKILL.md contains no URLs. Its commands use pip, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Re Attribution is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.1k tokens (SKILL.md is roughly 4.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.9k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Re Attribution: C To Ast (Narwhal-Lab/MagicSkills, 316 stars), Security Audit (TheDecipherist/claude-code-mastery, 550 stars), Vpn Security Check (Sergei-thinker/vpn-setup, 189 stars) and Bandit (alpha-omega-security/scrutineer, 231 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
dslsdzc (a GitHub user) maintains it in dslsdzc/rev-skills, which has 125 GitHub stars. The repository holds 41 skills in this directory. The repository was last updated on October 5, 2026.
Source: dslsdzc/rev-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.